WordPress Plugin Vulnerabilities

Open Graph < 1.11.3 - Unauthenticated Sensitive Information Exposure

Description

The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.11.2 via the 'opengraph_default_description' function. This makes it possible for unauthenticated attackers to extract sensitive data including partial content of password-protected blog posts.

Affects Plugins

Fixed in 1.11.3

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Krzysztof Zając
Verified
No

Timeline

Publicly Published
2024-06-04 (about 2 years ago)
Added
2024-06-05 (about 2 years ago)
Last Updated
2024-06-06 (about 2 years ago)

Other